Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted c...
Amazon CVEs
15 high and critical vulnerabilities covered by CVE Brief since 2025-10-09, each with independent analyst commentary.
← All vendorsProfile
Last 12 months
15 CVEs in the last 12 months
Products
- Amazon Athena ODBC driver5
- ion-java1
- log4j-cve-2021-44228-hotpatch1
- awslabs.dynamodb-mcp-server1
- amazon-ssm-agent1
- Amazon Redshift JDBC Driver1
- Workspaces1
- Kiro CLI1
11 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary...
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might al...
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an aut...
An issue exists in Amazon Redshift JDBC Driver versions prior to 2
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2
An uncontrolled search path element in Kiro CLI before version 2
An uncontrolled search path element in Kiro IDE before version 1
Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023
An infinite loop issue in Amazon